SB20260828194 - Out-of-bounds read in Linux kernel qlogic qede driver
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-80609)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the qede driver qede_tpa_cont and qede_tpa_end handling of cqe->len_list[] when processing crafted CQE data. A local user can trigger access past the end of the len_list array to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1aacefd074b5dcc99b8dbcd73e1c963ed5010110
- https://git.kernel.org/stable/c/6d203bdd227fca1787f8a80cf84b990936633c5a
- https://git.kernel.org/stable/c/6d46ab395803f162cdc50e8d346e5f1a4e766771
- https://git.kernel.org/stable/c/b17751a2ebc4aef3ce6be6f71ee8df92bf5ddfcd
- https://git.kernel.org/stable/c/bd3a6a083b408e96437dbd86ff543ba9ec3a788b
- https://git.kernel.org/stable/c/e30af53dca803893a29eb3bbe0539752ba435410
- https://git.kernel.org/stable/c/f9ba47fce5932c15891c89c60e76dfaca919cb8d